Remote Code Execution Vulnerability in MOOS-IvP by MOOS-IvP
CVE-2026-85439
8.5HIGH
What is CVE-2026-85439?
The MOOS-IvP platform, up to version 24.8.1, contains a significant remote code execution vulnerability in the SplitHandler::handlePreCheckSplitDir() function of alogsplit. This vulnerability allows attackers to exploit insufficient sanitization of shell metacharacters in log file pathnames. By embedding shell syntax in log file names or the --dir command-line parameter, an attacker gains the ability to execute arbitrary commands with the privileges of the user running alogsplit, potentially compromising system integrity and security.
Affected Version(s)
moos-ivp 0 <= 24.8.1
